CVE-2022-27305
NixOS vulnerability analysis and mitigation

Overview

A session fixation vulnerability was identified in Gibbon Core, affecting all versions prior to v23.0.02. The vulnerability was discovered in March 2022 and was assigned CVE-2022-27305. Gibbon v23 did not generate a new session ID cookie after user authentication, making the application vulnerable to session fixation attacks (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-384 (Session Fixation) with a Moderate severity rating. The core issue lies in the application's failure to generate new session ID cookies post-authentication, which could potentially allow attackers to exploit user sessions (GitHub Advisory).

Impact

While there was no evidence of exploitation in the wild, the vulnerability posed a significant security risk that warranted immediate attention from system administrators. The issue affected all versions of Gibbon Core prior to version 23.0.02 (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in Gibbon v23.0.02 release (Ga Yau Security Update). For installations unable to update to the latest version, patches were provided for v22.0.01 and v21.0.01, which could be applied by replacing the login.php file in the Gibbon root directory. Systems running the cutting edge code were advised to update to the latest commit of v24.0.00 (GitHub Advisory).

Community reactions

The security researcher Kole Swesey was acknowledged for responsibly disclosing the vulnerability to the Gibbon team. The team collaborated with the researcher to verify the fix and followed responsible disclosure practices (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management